Active threats

Organisations claimed as victims on ransomware groups' leak sites, classified by country and sector, and cross-checked with press coverage.

Claimed victims14
In Spain15
Confirmed by press0

Most active groups

  1. Qilin3
  2. Metaencryptor3
  3. The Gentlemen2
  4. Killsec31
  5. Everest1
  6. Audit Team1
  7. Eclipse1
  8. Vexy1
  9. Safepay1

Most affected countries

  1. United States242
  2. Canada28
  3. Germany27
  4. France25
  5. Italy21
  6. Brazil20
  7. Australia15
  8. Spain15
  9. Japan14
  10. India13

Most affected sectors

  1. Manufacturing4
  2. Technology4
  3. Automotive2
  4. Other2
  5. Media & entertainment1
  6. Professional services1

Recent victims

OrganisationGroupCountrySectorClaimedStatus
The Japan TimesEclipseJapanMedia & entertainment9/30/2026◌ Claimed (unverified)
Nissho Electric Manufacturing Co., Ltd.QilinJapanManufacturing9/28/2026◌ Claimed (unverified)
🔒 Organización sin información disponible (JP)Killsec3JapanOther9/27/2026◌ Claimed (unverified)
Corona CorporationMetaencryptorJapanManufacturing9/26/2026◌ Claimed (unverified)
Astemo LtdMetaencryptorJapanAutomotive9/26/2026◌ Claimed (unverified)
Nippon Steel CorporationMetaencryptorJapanManufacturing9/26/2026◌ Claimed (unverified)
UNIRITAEverestJapanTechnology9/25/2026◌ Claimed (unverified)
Ikegami Tsushinki Company LimitedQilinJapanTechnology9/21/2026◌ Claimed (unverified)
Kit-eAudit TeamJapanOther9/18/2026◌ Claimed (unverified)
Hashimoto JimukiVexyJapanTechnology9/15/2026◌ Claimed (unverified)
RyomoSafepayJapanTechnology9/15/2026◌ Claimed (unverified)
Sarku JapanThe GentlemenJapanAutomotive9/14/2026◌ Claimed (unverified)
TENTAC Co., LtdThe GentlemenJapanManufacturing9/14/2026◌ Claimed (unverified)
Mitsuwa Trading Co., LtdQilinJapanProfessional services9/9/2026◌ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.